Justin's repositories

zeek-pdns

Passive DNS collection using Zeek

Language:GoLicense:MITStargazers:181Issues:21Issues:11

flow-indexer

Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files

can-i-use-afpacket-fanout

Validate if afpacket PACKET_FANOUT_HASH is working properly

pynfdump

python wrapper for the nfdump cli application

ssh-auth-logger

A low/zero interaction ssh authentication logging honeypot

Language:GoStargazers:18Issues:5Issues:0

bannerscanner

simple tcp port scanner + banner grabber

Language:GoStargazers:14Issues:2Issues:0

bro-react

react stuff

Language:ZeekStargazers:8Issues:2Issues:0
Language:GoStargazers:4Issues:3Issues:0

zeek-log-filtering

A bunch of examples of zeek log filtering

Language:ZeekStargazers:4Issues:2Issues:0

zeek-jemalloc-profiling

a zeekctl plugin that helps configure MALLOC_CONF for profiling

Language:PythonLicense:MITStargazers:2Issues:2Issues:2

bro-bench

work in progress bro benchmarking tool

suricata

Suricata git repository maintained by the OISF

Language:CLicense:GPL-2.0Stargazers:1Issues:3Issues:0

wifi-wpa

wifi daemon for connecting to unencrypted networks with gokrazy

Language:GoLicense:NOASSERTIONStargazers:1Issues:1Issues:0

credit-card-exposure

Detect credit card exposures with Bro

Language:ZeekLicense:NOASSERTIONStargazers:0Issues:1Issues:0

CVE-2020-14882-weblogicRCE

Detection of RCE in Oracle's WebLogic Server CVE-2020-14882 / CVE-2020-14750

Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0
Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0
Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

go-opendecompress

like os.Open, but automatically decompress files

Language:GoStargazers:0Issues:2Issues:0

ipviz

Visualize zeek conn logs using a hilbert space filling curve

Language:GoStargazers:0Issues:1Issues:0

package-manager

A package manager for Zeek

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

partial_md5

Figure out if it's possible to truncate a large file so that it has a particular md5.

Language:GoStargazers:0Issues:1Issues:0

pcap_simplify

pcap format simplification stuff

Language:GoStargazers:0Issues:2Issues:1

pingback

A Zeek package to detect the Pingback malware ICMP tunnel command and control (C2) network traffic.

Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

raspi-corelight

Corelight@Home script

Language:ShellLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

ssh-auditor

The best way to scan for weak ssh passwords on your network

Language:GoLicense:NOASSERTIONStargazers:0Issues:1Issues:0

website

Source code for website.

Language:CSSStargazers:0Issues:1Issues:0

wifi

Package wifi provides access to IEEE 802.11 WiFi device actions and statistics. MIT Licensed.

Language:CLicense:MITStargazers:0Issues:1Issues:0

zeek-long-connections

Zeek package for tracking long connections to report them before they have completed.

Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0